start>run>gpedit.msc
User Configuration>Administrative Templates>System>Run only allowed Windows applications
Configure the list of allowed apps here.
If you REALLY want to lock it down, Prevent access to the command prompt in System will stop even more installs.
explore gpedit.msc there's a lot of good stuff there!